backend · easy
Session cookie
Server-side session id (or signed payload) stored in a cookie so later requests know who is logged in.
Where you see it
Rails `session[]` is typically a signed/encrypted cookie. `flash` is a one-request session slice for “Post created.” HttpOnly and Secure flags matter. Contrast with JWTs in localStorage — different tradeoffs.
Why it matters
Most HTML fullstack apps still authenticate with sessions. Take-homes that skip CSRF and cookie flags fail production review.
Tags: rails, nodejs
